CVE-2020-7010: High severity elastic cloud on kubernetes vulnerability
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7010?
CVE-2020-7010 is a vulnerability in Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 that allows an attacker to more easily brute force Elasticsearch credentials.
What is the severity of CVE-2020-7010?
CVE-2020-7010 has a severity rating of high, with a CVSS score of 7.5.
How does CVE-2020-7010 impact Elastic Cloud on Kubernetes (ECK)?
CVE-2020-7010 impacts ECK versions prior to 1.1.0 by generating passwords using a weak random number generator, making it easier for attackers to brute force Elasticsearch credentials.
How can I mitigate the vulnerability in CVE-2020-7010?
To mitigate the vulnerability, it is recommended to upgrade Elastic Cloud on Kubernetes (ECK) to version 1.1.0 or higher.
Where can I find more information about CVE-2020-7010?
For more information about CVE-2020-7010, you can refer to the official security advisory on the Elastic website.